Skip to content
Adrythm
Email, texting and privacy

Right to delete

CCPA right to delete / CCPA deletion request / request to delete personal information

In short

The CCPA right to delete lets a California consumer ask a covered business to erase personal information collected from them. Unless an exception applies, the business deletes it within 45 days, extendable once by 45 when reasonably necessary with notice. It also notifies service providers, contractors and, unless impossible or disproportionate, third parties it sold or shared data with.

A deletion request under California Civil Code section 1798.105 reaches past the business's own files. The business deletes the personal information from its records and notifies its service providers or contractors to delete it. It also notifies third parties it sold or shared the information with, unless this proves impossible or involves disproportionate effort.

At the business's direction, service providers and contractors delete the data or enable the business to delete it. They notify their own service providers or contractors. They also notify others who accessed the data through them, unless the business directed that access, or notice proves impossible or involves disproportionate effort. A vendor need not act on a deletion request a consumer sends it directly about data it handles for the business.

Under section 1798.130, a business must offer at least two ways to submit a request, including a toll-free number. An exclusively online business with a direct relationship with the consumer may use an email address instead. Separately, any business with a website must accept requests through it. No business may make someone create an account to ask, though it may send existing account holders through their account.

The California Privacy Protection Agency says a business must confirm receipt within 10 business days. It has 45 days from receipt to delete, and verification time counts against those days. It may extend once by 45 more days when reasonably necessary, with notice inside the first 45 days.

Section 1798.105 lists eight grounds for keeping data where reasonably necessary. They include completing the transaction, a written warranty or product recall, a good or service the consumer requested or would reasonably expect, and a contract. Others cover security, debugging, free speech or another legal right, the California Electronic Communications Privacy Act, expected internal uses, and a legal obligation. Consented research qualifies where deletion would seriously impair it.

The Attorney General's FAQ lists other common reasons and points to section 1798.145 for more. They include an unverifiable request, data needed to exercise or defend legal claims, and data exempt from the CCPA, such as publicly available information. A business may also keep a confidential record of deletion requests. The record may serve solely to keep the requester's information from being sold, to comply with laws, or for other purposes the CCPA permits.

In practice

A landscaping company covered by the CCPA gets a website deletion request from a past customer. It confirms receipt, verifies the person, and deletes the contact from its own customer list. It tells its email platform, call tracking vendor and other service providers holding the record to delete it. If an ad platform that counts as a third party received the list, it notifies that platform too. It keeps a confidential record of the request and any records a law requires, and responds within 45 calendar days.

Not the same as

Right to opt-out of sale or sharing
An opt-out stops a business from selling or sharing personal information after the request. A deletion request asks the business to erase information it collected. The business also notifies its service providers and contractors, and third parties it sold or shared the data with unless that proves impossible or involves disproportionate effort.

Why it matters to you

Customer details live in the email platform, quote software, call tracking and ad tools. A request handled only in the main inbox leaves copies the statute expects notices to reach. A policy without a toll-free number misses the rule unless the online-only exception applies.

What to ask or check

  1. 01Which request methods does your privacy policy list, including a toll-free number, and who watches them?
  2. 02Which vendors hold customer personal information, and is each a service provider, contractor or third party?
  3. 03How does the business verify a requester, and who tracks the 45-day deadline?
  4. 04Which records does the business keep after a deletion request, and which exception covers each one?

What people get wrong

That a deletion request reaches only the business's own records. California Civil Code 1798.105 requires the business to notify its service providers and contractors. It must also notify third parties it sold or shared the data with, unless that proves impossible or involves disproportionate effort.

Red flags

  • A deletion request process that makes a person without an account create one first.
  • A privacy policy that offers a web form as the only way to submit a request.
  • No record of which vendors hold customer personal information on the business's behalf.

CCPA business thresholds

The CCPA business thresholds are the three tests that decide whether California's privacy law covers a for-profit company doing business in the state. Meeting any one is enough: revenue above $26,625,000 a year, buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half its revenue from selling or sharing it.

Notice at collection

A notice at collection is the disclosure California's privacy law requires before or as a covered business collects personal information. It says what is collected and why, whether it is sold or shared, and how long it is kept. So it belongs wherever the information is gathered, such as a website form.

Global Privacy Control

Global Privacy Control is a signal a web browser sends to every site a person visits, saying they do not want their personal information sold or shared. California's CCPA counts it as a valid opt-out request, and Colorado recognizes it as a universal opt-out, so covered businesses must honor it automatically.

Unsubscribe

Unsubscribing has a legal shape and a technical one. The law allows a reply or a single web page, with no fee and no information beyond the address, honored within 10 business days. The one-click standard exists because automated scanners were unsubscribing people by accident.

DKIM

DKIM attaches a cryptographic signature to a message so a receiver can confirm the signed parts were not altered. The standard describes it as a domain claiming some responsibility for the message, and it separates the signer from the purported author. Modifying a message in transit breaks the signature.

SPF

SPF is a DNS record listing which servers may send mail using your domain in the envelope sender. The specification caps it at ten DNS-querying terms, and receivers must return permerror if that is exceeded, which means the check fails. It does not check the From address a recipient sees.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.